Security changelogs

October 2016
Fixed in version 15.12
26 October 2016, 09:00

CVE-2016-8501: Vladimir Dubrovin

Security WiFi bypass in Yandex Browser for desktop from version 15.10 to 15.12 allows remote attacker to sniff traffic in open or WEP-protected Wi-Fi networks despite of special security mechanism is enabled.

No comments
CVE-2016-8501
Fixed in version 16.2
26 October 2016, 09:05

CVE-2016-8502: Evgeny Sukhov

Yandex Protect Anti-phishing warning in Yandex Browser for desktop from version 15.12.0 to 16.2.0 could be used by a remote attacker for brute forcing passwords from important web-resource (without opportunity of getting login or important resource's address) with special JavaScript-code.

CVE-2016-8506: Thereissuchname

XSS in Yandex Browser's Translator in Yandex Browser for desktop for versions from 15.12.0 to 16.2.0 could be used by a remote attacker for evaluation arbitrary JavaScript-code.

No comments
CVE-2016-8502,CVE-2016-8506
Fixed in version 16.6
26 October 2016, 09:10

CVE-2016-8504: Ziyahan Albeniz

CSRF of synchronization form in Yandex Browser for desktop before version 16.6 could be used by remote attacker to steal saved data in browser profile.

CVE-2016-8505: Jouko

XSS in Yandex Browser's BookReader in Yandex browser for desktop for versions before 16.6. could be used by remote attacker for evaluation arbitrary JavaScript-code.

No comments
CVE-2016-8504
Fixed in version 16.9
26 October 2016, 09:20

CVE-2016-8503: Evgeny Sukhov

Yandex Protect Anti-phishing warning in Yandex Browser for desktop from version 16.7.0 to 16.9.0 could be used by a remote attacker for brute-forcing passwords from important web-resource (without opportunity of getting login or important resource's address) with special JavaScript-code.

No comments